Zoom Chrome Extension For Gov
pnlbnejodfpnapdpoiboebofddaejkbg
Risk Score
3.12
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — policy admits sharing but does not scope to this extension.
- install_url_hijack flag set true; onInstalled behaviour opens external URL (target null, but flag is authoritative).
- Operator cluster has 1 sibling extension under same fingerprint; warrants cross-check.
- CSP script-src allows remote *.google.com and *.zoomgov.com domains — remote script execution possible from those origins.
- No ratings/reviews (0 rating, 0 count) limits social-proof signal; low install count for a gov-facing tool.
Evidence
- privacy_policy_generic api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
- install_url_hijack crx install_url_hijack=true; target null. Rubric: onInstalled opens 3rd-party URL +2.0 Webstore.
- operator_cluster api sibling_count=1 (kgjfgplpablkjnlkjmjdecgdpfankdle); +2.5 Webstore per rubric.
- csp_remote_script_src manifest script-src includes https://*.google.com https://*.zoomgov.com — allows remote script loads from those origins.
- confirmed_owner_no_impersonation api brand_mention.confirmed_owner=true, is_impersonation=false; developer domain zoom.us resolves.
- no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 has no known CVEs.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0; no exfil or eval indicators.
- recently_updated store months_since_update=1; Maintenance pillar = 0.0.
Permissions Breakdown
- storage low Local key-value storage; no cross-site exposure.
- unlimitedStorage low Removes storage quota; low direct risk without other broad permissions.
- host: https://www.google.com/calendar/* medium Content-script / request access scoped to Google Calendar only.
- host: https://calendar.google.com/calendar/* medium Content-script / request access scoped to Google Calendar only.
- host: https://*.zoomgov.com/* medium Broad wildcard on gov Zoom subdomain; acceptable for stated function.
Pillar Scores
Permissions1.50
Reputation3.00
Network1.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
547ba45b0eaf…
Force block
— not fired
Score recovered
no
Elapsed
23.6s